Microsoft has made writeback for Cloud-Managed Remote Mailboxes generally available. Hybrid organizations can move the source of authority for supported mailbox attributes to Exchange Online, keep the user identity synchronized from on-premises Active Directory, and use Microsoft Entra Cloud Sync to write designated Exchange changes back to Active Directory.
This closes a practical gap for organizations that moved mailbox data to Exchange Online but kept an Exchange Server solely because supported recipient management still depended on it. The GA release is a major step toward retiring that last server—but it is not permission to uninstall Exchange without a dependency assessment.
The architecture in plain language
| Component | Responsibility after the change | Important boundary |
|---|---|---|
| On-premises Active Directory | Remains authoritative for the user’s synchronized identity attributes. | The user is still directory-synchronized; this is not a full user source-of-authority transfer. |
| Exchange Online | Becomes authoritative for supported Exchange attributes when IsExchangeCloudManaged is true. | The flag applies to mailboxes, not mail-enabled groups or contacts. |
| Microsoft Entra Connect Sync | Can continue synchronizing identities and existing directory attributes. | It does not need to be removed for this design. |
| Microsoft Entra Cloud Sync | Writes the supported Exchange attribute set from the cloud back to Active Directory. | Cloud Sync and the Exchange writeback configuration are required when on-premises applications need current copies. |
What changed at general availability
Microsoft raised the supported scale from fewer than 200,000 mailboxes during preview to up to 600,000 cloud-managed mailboxes per tenant. Availability covers worldwide commercial, GCC High, DoD, and 21Vianet environments.
The GA release also adds the mail attribute to the supported writeback set. A change to WindowsEmailAddress in Exchange Online can now update the corresponding mail value in on-premises Active Directory.
Microsoft documents 24 supported writeback attributes, including:
extensionAttribute1throughextensionAttribute15msExchExtensionCustomAttribute1throughmsExchExtensionCustomAttribute5msExchRecipientDisplayTypeandmsExchRecipientTypeDetailsproxyAddressesmail
That list is deliberately bounded. Inventory every application, script, synchronization rule, and provisioning workflow that reads or writes Exchange-related attributes before assuming writeback covers it.
Existing preview configurations need one specific review
Exchange attribute writeback configurations created on or after August 3, 2026 include the mail mapping by default. Microsoft says configurations created before that date are not automatically updated.
If the organization enabled writeback during preview, review the configuration in the Microsoft Entra admin center. Microsoft’s documented path is to open the attribute mappings and use Restore default mappings, then allow the synchronization job to restart. Test that behavior in a controlled group first, especially if the preview mapping was intentionally customized.
Mailbox-by-mailbox transfer is the safer starting point
For a directory-synchronized mailbox, setting IsExchangeCloudManaged to true transfers the Exchange-attribute source of authority to Exchange Online. Supported properties that were previously locked in the cloud can then be managed with Exchange Online PowerShell, the Exchange admin center, or the Microsoft 365 admin center.
Start with a representative pilot rather than tenant-wide enablement. Include mailboxes with aliases, custom attributes, delegates, retention, line-of-business dependencies, and different organizational units. Capture the source values, synchronize completely, flip the mailbox, make controlled changes in Exchange Online, and prove that the expected attributes return to Active Directory.
Microsoft also supports moving an individual mailbox’s Exchange-attribute authority back on-premises by setting IsExchangeCloudManaged to false. Before doing so, export cloud values that must be retained: the next sync cycle can replace cloud Exchange attributes with the on-premises values.
Do not enable tenant-wide SOA too early
Microsoft’s strongest warning concerns the tenant-wide default. Enable tenant-wide Exchange attribute source of authority only after:
- All on-premises mailboxes have been migrated to Exchange Online
- The organization no longer creates Exchange mailboxes, mail-enabled users, or remote mailboxes on-premises
- Recipient provisioning has been redesigned and tested for the cloud-managed model
- Mail-enabled groups and contacts have a separate supported management plan
If tenant-wide SOA is enabled while on-premises recipient creation continues, a newly synchronized object can arrive in Microsoft Entra ID as an identity-only user instead of the required Exchange MailUser. That can block mailbox onboarding, and Microsoft warns that affected objects may require support-assisted recovery.
Writeback is optional when nothing on-premises reads the values
Cloud-based management and writeback solve different problems. A mailbox can be managed in Exchange Online without writing its Exchange attributes back to Active Directory. Writeback is needed when on-premises applications, scripts, address workflows, or identity processes still rely on those Active Directory values.
Do not deploy Cloud Sync merely because the feature exists. First identify the consumer. If no supported business process reads proxyAddresses, custom attributes, recipient type values, or mail from Active Directory, the additional synchronization path may not be necessary.
A controlled pilot blueprint
| Stage | Action | Proof required |
|---|---|---|
| Inventory | Map mailbox, group, contact, application, script, and attribute dependencies. | Every Exchange attribute consumer has an owner and disposition. |
| Prepare | Validate supported sync versions, roles, Cloud Sync agents, scoping, network access, and rollback exports. | The lab can run a full sync and restore original values. |
| Pilot mailboxes | Transfer a small representative group with IsExchangeCloudManaged. | Cloud edits work and expected attributes write back without collisions. |
| Operationalize | Define provisioning, change control, monitoring, failure response, and service-desk ownership. | A normal joiner, change, and leaver cycle succeeds end to end. |
| Expand | Move mailbox cohorts while separately addressing groups, contacts, and exceptional applications. | No unsupported recipient-management dependency remains on the server. |
| Decommission | Follow Microsoft’s last-server prerequisites, uninstall, hybrid cleanup, and post-removal checks. | Mail flow, administration, sync, recovery, and monitoring remain supported. |
What still blocks last-server retirement
Cloud-managed mailbox attributes do not cover every Exchange object or every hybrid dependency. Before uninstalling the last server, assess:
- On-premises mailboxes, public folders, and migration batches
- Mail-enabled groups and contacts that need active management
- SMTP relay, scanners, applications, and devices
- Hybrid mail flow, connectors, accepted domains, certificates, and DNS
- Third-party tools that call on-premises Exchange cmdlets or read Active Directory attributes
- System and arbitration mailboxes or databases that block uninstall
- Monitoring, recovery, emergency access, and post-change ownership
Microsoft’s decommissioning guide is the runbook baseline. Use the writeback GA as a project enabler, not as a substitute for that checklist.
Frequently Asked Questions
Does the user become cloud-only? No. In this model, the user identity remains synchronized from on-premises Active Directory; only supported Exchange attributes move to cloud authority.
Can Connect Sync and Cloud Sync run together? Yes. Microsoft says Connect Sync can continue for identities while Cloud Sync handles Exchange attribute writeback.
How many mailboxes are supported? The GA release supports up to 600,000 cloud-managed mailboxes per tenant.
What changed for preview customers? Configurations created before August 3, 2026 need a mapping review if they should write back the newly supported mail attribute.
Does the feature manage groups and contacts? IsExchangeCloudManaged applies to mailboxes. Groups and mail contacts require their own source-of-authority transfer approach.
Can we uninstall Exchange immediately? No. Complete Microsoft’s recipient, mail-flow, public-folder, application, hybrid, and uninstall prerequisites first.
Retire the last Exchange Server without breaking hybrid identity
Accred Consulting can inventory recipient dependencies, design the Cloud Sync writeback model, run a controlled mailbox pilot, remediate groups and contacts, and execute Microsoft’s supported last-server decommissioning path.
Assess Last-Server Readiness